First published: Fri May 20 2022(Updated: )
Multiple DLL hijacking vulnerabilities via the components instup.exe and wsc_proxy.exe in Avast Premium Security before v21.11.2500 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted DLL file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avast Premium Security | <21.11.2500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28965 is a vulnerability that allows attackers to execute arbitrary code or cause a Denial of Service (DoS) in Avast Premium Security before v21.11.2500.
An attacker can exploit CVE-2022-28965 by using a crafted DLL file to hijack the components instup.exe and wsc_proxy.exe in Avast Premium Security.
CVE-2022-28965 has a severity rating of 6.5 (medium).
Avast Premium Security versions before v21.11.2500 are affected by CVE-2022-28965.
Yes, updating Avast Premium Security to version 21.11.2500 or later fixes CVE-2022-28965.